BOTECH's New Merchant Portal: agile, secure, multi-device PCI DSS v4.0.1 certification

In a constantly evolving digital ecosystem, ensuring the security of online transactions and mitigating payment card fraud has become an essential strategic priority for any business. For organizations that accept, process, store or transmit payment card data, complying with the international PCI DSS (Payment Card Industry Data Security Standard) is not just a regulatory obligation, but the cornerstone that sustains their customers' trust.

Aware of this challenge, especially for Level 4 merchants (those processing fewer than 20,000 transactions per year) and travel agencies affiliated with IATA (International Air Transport Association), at BOTECH we have completely revamped our Merchant Portal.

The new Merchant Portal is not just a cosmetic update. It is designed to eliminate the fragmentation of the process, reduce user friction and ensure agile, guided PCI DSS v4.0.1 compliance.

The big leap: from the browser to a multi-device cloud account

One of the most significant limitations of the previous version was the way progress was stored. In the first version, the certification questionnaire's progress was saved locally in the user's own browser. This meant that if the merchant switched devices, accidentally cleared their browsing data, or simply wanted to review the process on a mobile phone, they lost all the information completed up to that point.

With the new portal, this obstacle disappears entirely. Now, progress is securely linked to a cloud account associated with the merchant's email address. Your work goes with you wherever you are: you can start the questionnaire on your phone in the morning, continue at midday on the office computer, and finish it in the afternoon from your tablet in the comfort of your home.

The 8 major new features of the new Merchant Portal

1. Centralized dashboard (everything in one place)

Merchants now have a centralized personal dashboard from which they can autonomously manage every step of the certification, and where it is possible to:

  • View the status and progress of the ongoing certification in real time, being able to pause and resume the questionnaire right where they left off.
  • Manage collaborators and their access flexibly.
  • Access invoices, receipts and downloadable documents.
  • Consult the complete activity history (logins, modifications, invitations and payments), an essential requirement for PCI DSS audits.

2. Teamwork with role assignment

Certification no longer has to rest on a single person's shoulders. The new portal allows you to invite external collaborators and distribute compliance tasks under three well-defined profiles:

  • Owner: the business holder and ultimate legal party responsible for the certification. Retains full control and manages access.
  • Editor: the person in charge of filling out the questionnaire (ideal for delegating this technical task to agencies, consultants or fully trusted collaborators).
  • Payer: the ideal role for the accounting or finance department, allowing the certification payment to be made in isolation without needing access to the technical content of the questionnaire.

3. "Passwordless" access, no passwords

In line with the usability best practices of online banking and major digital platforms, we have eliminated traditional passwords. To access the portal, the user simply enters their email address and instantly receives a temporary access link. This way we eliminate the classic "I forgot my password" problem.

4. Modern, responsive interface (UI/UX)

The design has been completely redesigned to be intuitive and responsive. The portal features a progress bar visible at all times so you know exactly how much is left to finish. It also allows sharing direct links to specific screens, making it easy for the owner to send a particular section of the questionnaire to the person assisting them at that step.

5. Smart assistant (AI chatbot) and built-in glossary

So that merchants don't feel lost when faced with PCI DSS v4.0.1 technical terminology, the portal incorporates a smart chatbot and a detailed glossary of terms at every step. This virtual assistant guides the user in real time and resolves questions on the fly, making it easier for people without advanced technical knowledge to complete the process securely.

6. Automatic translation of answers into English

Complying with global standards requires international tools. The portal includes a unique feature that automatically translates the merchant's answers from Spanish into English. This way, the resulting certification documents (downloadable directly in PDF format) immediately comply with the international formats recommended and required by the card brands (such as VISA, Mastercard, JCB, Discover and American Express).

7. Billing and accounting always available

There is no longer any need to search through your email inbox to find payment receipts. All payment documentation (receipt, simplified invoice and full invoice in PDF format) is generated automatically and stored in the merchant's dashboard for download at any time.

8. Ready to grow: scalability and white label

The portal has been built with a modular architecture ready to incorporate new languages and future certifications without altering its basic operation. In addition, a white-label version can be enabled for large companies or BOTECH partners who wish to offer PCI DSS certification to their own clients under an independent, customized environment with their own corporate identity.

Reinforced security: the core of BOTECH

As cybersecurity specialists with almost 15 years of global experience, protecting the data collected during certification is our top priority. That is why the new version of the portal includes:

100% encrypted communications

Using the most advanced cryptographic standards on the market.

Top-tier cloud infrastructure

Ensuring high availability, automated backups and encryption of data at rest.

Comprehensive audit log

Of all important activities carried out during the process, ensuring regulatory compliance from the outset.

Especially designed for the tourism industry and travel agencies (IATA)

The leak or theft of sensitive card data can ruin a business through direct financial penalties, the loss of the right to operate with cards, and irreparable reputational damage. In the tourism sector, IATA strictly requires PCI DSS compliance from all its affiliated agencies to mitigate fraud in commercial aviation.

Thanks to our revamped BOTECH Merchant Portal, IATA-affiliated travel agencies managing fewer than 20,000 transactions per year can achieve their certification in a guided, simple, agile and flexible way, demonstrating to their clients and partner airlines that the integrity and privacy of their data are completely safe.

Take the step toward a safer business!

Enter our BOTECH Merchant Portal today, complete your questionnaires in a guided way and get certified under PCI DSS v4.0.1 in an agile, fast way, with the support of our team of experts.

Request information